Skip to content
StudiO
Legal

Privacy policy

What OLSYN StudiO collects, why, who else sees it, how long we keep it, and what you can ask us to do about it.

1. Structure and scope

This privacy policy governs access to and use of the Olsyn website and the Olsyn StudiO digital twin platform (the "Services"). This policy operates in conjunction with our Information Security Policy and Data Governance Policy.

In this policy, "Olsyn", "we", "us" or "our" means Olsyn Pty Ltd. "You" or "your" means the individual visiting our website or accessing the Services. Where you access the Services on behalf of an organisation, your organisation's master agreement governs the corporate data ingested into the platform.

2. Information we collect

We limit our collection of information to what is strictly necessary to deliver, secure and operate our platform:

  • Information provided directly. Contact and demo enquiries (name, corporate email, company and message details), user account credentials and general business correspondence.
  • Operational materials and uploads. Vector PDFs, CAD files, spatial plans, drawings, images and project data uploaded to StudiO. Customers must ensure no unnecessary personal information is included within uploaded project files.
  • Automated system and security logs. IP addresses, browser specs, user agents, access timestamps and request logs generated during normal platform operations to maintain security, system availability and audit trails.
  • Technical analytics. Anonymised operational telemetry and interaction metrics used to evaluate platform performance, as outlined in Section 8.

3. Purpose of processing and data commercialisation

We process information solely to provide, support, maintain and secure the Olsyn StudiO platform, fulfil contract obligations, verify user access and meet statutory compliance obligations under Australian law.

Commercialisation disclaimer. Olsyn does not sell, rent, trade, lease or commercialise personal information, uploaded project files or customer data in any form. Furthermore, Olsyn does not sell or monetise de-identified, aggregated or anonymised datasets derived from customer data to third parties.

4. Statutory grounds for processing

We process information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and our Privacy & APP Compliance Policy. Processing relies on: the performance of a contract; compliance with legal and regulatory obligations; your explicit consent; or our legitimate business operational interests where not overridden by individual privacy rights.

5. Disclosure and corporate restructuring

We do not disclose information to third parties except to bound service providers (cloud infrastructure, hosting, secure communications and professional advisers) acting strictly under our instructions.

In accordance with our Software & Service Agreement, in the event of a corporate restructure, financing, merger, acquisition, sale of shares or sale of business assets, customer data and personal information may be transferred to an Affiliate or acquiring entity, provided that party assumes Olsyn's privacy obligations and continues to protect the information to a standard consistent with this policy.

6. International transfers and data sovereignty

Olsyn prioritises data sovereignty. Primary platform hosting and data processing are maintained within Australian data centre jurisdictions. Where operational dependencies require international data processing or storage, Olsyn enforces strict contractual, technical and organisational measures to ensure cross-border transfers remain fully compliant with Australian Privacy Principles and applicable data sovereignty regulations.

7. Data retention and lifecycle management

  • Account and contact data. Retained for the duration of the commercial relationship and a reasonable operational period thereafter for compliance and auditing.
  • Uploaded files and digital twins. Retained for the active subscription term. Upon account termination, data is made available for export for 30 days and subsequently purged in accordance with Olsyn's data-retention procedures, subject to routine disaster recovery backups and statutory compliance requirements.
  • System logs. Retained for defined security and audit cycles as specified in the Olsyn Cookie Management Policy.

8. Telemetry, cookies and analytics

The platform utilises essential session cookies and privacy-focused, anonymised analytics to ensure system security, maintain active user sessions and evaluate feature performance. We utilise cookieless or de-identified interaction tracking methods that do not construct advertising profiles or track users across external third-party sites. Browser cookie controls can be managed locally; however, disabling necessary operational cookies may affect platform utility.

9. Security and notifiable data breaches

Olsyn implements industry-best-practice administrative, physical and technical controls, including end-to-end transport encryption, role-based access controls and vulnerability monitoring, aligned with ISO 27001 and SOC 2 standards.

In the event of a confirmed or reasonably suspected Eligible Data Breach affecting personal information, Olsyn will execute its Incident Response Plan, implement containment measures without undue delay and fulfil all statutory notification obligations to affected individuals and those required under the Australian Notifiable Data Breaches scheme.

10. Rights and access requests

Subject to applicable laws, individuals may request access to, correction of or deletion of their personal information held by Olsyn. Requests should be submitted to the contact point in Section 13. Responses will be provided within statutory timeframes. If an issue remains unresolved, individuals retain the right to escalate inquiries to the OAIC or relevant jurisdictional regulator.

11. Minors and age restrictions

Olsyn StudiO is a business-to-business enterprise platform and is not directed at or designed for use by minors. Olsyn does not knowingly collect or process personal information from children under the age of 18, in alignment with Australian Online Safety codes and regulatory frameworks governing minors.

12. Policy governance and variations

This policy is reviewed annually or upon material operational changes. Updates are published to the Olsyn Trust Center with an updated effective date. Material variations affecting customer rights will be communicated through official platform channels.

13. Contact and compliance inquiries

For privacy inquiries, subject access requests or regulatory compliance matters, contact privacy@olsyn.com or use the contact form.